Answer vulnerable to account takeover because password reset links do not expire in github.com/answerdev/answer
{ "url": "https://pkg.go.dev/vuln/GO-2023-1719", "review_status": "UNREVIEWED" }